FILTERING BY: CLEAR FILTER

GitHub API Exploitation via Aged 'Ghost Accounts'

Threat actors are executing coordinated reconnaissance campaigns against corporate entities by leveraging "Ghost Accounts"—dormant GitHub profiles aged 2-5 years designed to bypass heuristic-based detection of new "burner" accounts. The attack utilizes a two-stage methodology: initial unauthenticated mapping of organizational social graphs via public GraphQL and REST API endpoints, followed by a high-velocity exfiltration phase. During this second phase, attackers utilize "Identity Dark Matter"—compromised OAuth tokens and Personal Access Tokens (PATs)—to pivot from public data to private repository cloning. This approach effectively evades traditional rate-limiting and anomaly detection by mimicking legitimate developer telemetry and leveraging high-abuse infrastructure like 3xK Tech.


LINK COPIED TO CLIPBOARD